~/wiki

oauth discovery

---
title: OAuth Discovery
category: concepts
created: 2026-12-21
updated: 2025-01-04
tags: [oauth, authentication, discovery, rfc-9728, rfc-7591, pkce, well-known, mcp, standardization, auth-handshake, dynamic-client-registration, spolu-analysis, mcp-cli-implementation, oauth-2-1, protected-resource-metadata, browser-flows, token-refresh, cli-integration-gap, standardization-opportunity, piggyback-infrastructure, auth-flow-automation, credential-management]
sources: [raw/articles/MCP vs CLI vs Code.md]
confidence: high
---

# OAuth Discovery

Standardized mechanism for automatically discovering and configuring OAuth 2.1 authentication flows, eliminating manual authentication setup for AI agents and services. Foundation of [model-context-protocol](/concepts/model-context-protocol)'s authentication architecture and potential solution for CLI/code execution contexts requiring service integration.

## Technical Implementation

**MCP Integration:**
- Built on OAuth 2.1 with RFC 9728 (Protected Resource Metadata) and RFC 7591 (Dynamic Client Registration)
- Exposes `/.well-known/oauth-protected-resource` endpoint
- Automatic discovery of authorization server and dynamic client registration
- Standard PKCE flow execution
- Complete auth handshake handled by protocol

**Process Flow:**
1. Agent discovers MCP server by URL
2. Client reads `/.well-known/oauth-protected-resource`
3. Automatic authorization server discovery
4. Dynamic client registration if needed
5. Standard PKCE flow with browser-based authentication
6. Token refresh and credential management

## CLI Integration Gap

**Current Limitations:**
No equivalent standardization exists for CLI or code execution in sandboxed environments. Each service integration requires custom authentication plumbing, creating significant friction for multi-service agent workflows.

**Example Challenge:**
When an agent needs to call the Linear API on behalf of a user through CLI/code execution, there's no standard way to:
- Trigger authentication flow
- Obtain and manage tokens  
- Resume execution after auth completion
- Handle token refresh automatically

## Standardization Opportunity

**MCP-CLI Implementation:**
The mcp-cli project has already re-implemented MCP's OAuth 2.1 layer as standalone CLI module, including:
- PKCE flow support
- Token refresh mechanisms
- Browser-based authentication flows
- Credential management

**Infrastructure Reuse:**
Since MCP's OAuth layer uses standard OAuth with discovery conventions, existing MCP provider infrastructure can be reused by CLI and code execution contexts. Services don't need new implementations—just adoption of the same `/.well-known/` discovery convention.

## Architectural Advantage

**Standardized vs Custom:**
- **MCP**: Define server by URL, complete auth handling automated
- **CLI/Code**: Each integration requires custom authentication implementation
- **Standardized CLI**: Could adopt same discovery conventions, piggyback on MCP OAuth infrastructure

**Enterprise Value:**
Automatic credential management and standardized auth flows reduce operational overhead in multi-service environments, particularly valuable for enterprise deployments requiring integration with dozens of authenticated services.

## See also

- [model-context-protocol](/concepts/model-context-protocol)
- [cli-agent-integration](/concepts/cli-agent-integration)
- [enterprise-ai](/concepts/enterprise-ai)
- [action-discovery](/concepts/action-discovery)
- [protocol-criticism](/concepts/protocol-criticism)